Privacy Policy

Last updated: May 2026

ParlaParla is built so that privacy isn't a promise — it's an architectural fact. What data we handle depends on which version you use. This policy explains exactly what each version does, what it doesn't, and what your rights are.

Three versions, three privacy profiles

Free (Mac App Store): runs entirely on-device with Apple Speech, or with your own OpenAI key. No ParlaParla servers involved. Pro (one-time $19, direct download): same — your audio goes from your Mac directly to your chosen engine. Cloud ($9.99/mo, direct download): we proxy your audio to OpenAI on your behalf via our Cloudflare Worker. The Cloud sections below only apply if you have an active Cloud subscription.

How your audio is handled — Free and Pro

When you dictate, audio is recorded locally and sent directly from your Mac either to Apple's on-device Speech framework (no network), or to OpenAI's API using your own API key. The audio does not pass through any ParlaParla server. Once transcription finishes, the audio is discarded. See OpenAI's API data policy for details on how they handle data sent with your key (short version: API requests are not used to train their models).

How your audio is handled — Cloud

When you dictate using the Cloud tier, audio is sent from your Mac to our Cloudflare Worker at parlaparla.io/api, which immediately forwards it to OpenAI using our shared API key. We do not store the audio. Once the transcription is returned to your Mac, the audio is discarded by both us and OpenAI (per their API policy). Both ParlaParla and OpenAI are data processors in this flow; you are the data controller. The transcribed text is returned only to your Mac and is never logged.

What we log — Cloud only

For Cloud subscribers we log per-request metadata (your license key, request timestamp, audio duration in seconds, OpenAI token counts, computed cost) so you can see your usage on /account and so we can enforce the 30 hours/month fair-use cap. We do not log the audio itself, the transcribed text, or any content. Logs are kept for 90 days for billing and abuse-prevention purposes.

How your API key is stored — Pro (BYOK)

If you use Pro with your own OpenAI API key, the key is stored locally on your Mac in app preferences and never transmitted to any ParlaParla server. The key leaves your Mac only when the app sends requests directly to OpenAI on your behalf.

License keys and activations

When you buy Pro or subscribe to Cloud, we receive your email address and a Paddle customer ID via Paddle's webhook. We generate a license key (PARLA-XXXX-...) and email it to you via Resend. Each time you activate the license on a Mac, we record the machine ID and machine name (so we can enforce the 3-Mac limit) plus the activation timestamp. You can deactivate any of your machines via Settings → License or on /account.

Payments

Paddle is the merchant of record for all paid versions. They handle payment data, VAT, refunds, and customer billing. We never see your card details. Paddle's privacy policy applies to the payment flow.

Analytics and telemetry

There is none in the app — no crash reporting, no event tracking, no pings. This marketing website uses minimal aggregate analytics with IP anonymization to understand traffic. None of it is tied to your license or app usage.

Sub-processors

Paddle (Ireland) — payment processing and license issuance. Cloudflare (US) — Worker hosting, R2 object storage for downloads, D1 database for license records and Cloud usage metadata. OpenAI (US) — transcription and AI cleanup, only for Cloud or BYOK users when actively dictating. Resend (US) — transactional email delivery (license keys, account notifications). Netlify (US) — marketing-site hosting.

Your rights

You can request a copy of your license + usage data, or full deletion of your account, by emailing [email protected]. We respond within 30 days. Deletion revokes any active license; refund eligibility follows Paddle's 14-day money-back policy.